HIGH🇵🇱 Wersja polska

CVE-2026-59245

CVSS 8.1v3.1pub. 2026-07-13upd. 2026-07-14

In the Apache Airflow FAB auth manager, a DAG whose `dag_id` is `DAGs` collided with the global all-DAGs permission resource name produced by `resource_name()`, so a user granted per-DAG `access_control` on that one DAG was silently granted the global all-DAGs permission (privilege escalation). The escalation triggers when a DAG named `DAGs` exists and a lower-privileged user is given per-DAG access to it, granting that user read/edit access to every DAG. Users are advised to upgrade to `apache-airflow-providers-fab` 3.7.2 or later, which disambiguates the resource-name collision.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
  • Apache Airflow Providers Fab

    APP
    Apache
    < 3.7.2
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
LPE
CWE
References

Related vulnerabilities

CVE-2026-59243CRITICAL9.8PL ✓same product

Apache Airflow FAB: pominięcie weryfikacji podpisu tokenu OAuth (Azure AD)

CVE-2024-42447CRITICAL9.8PL ✓same product

Apache Airflow Providers FAB — nieprawidłowe wygasanie sesji (CWE-613)

CVE-2024-45033HIGH8.1same product

Insufficient Session Expiration vulnerability in Apache Airflow Fab Provider. This issue affects Apache Airfl...

CVE-2026-46745MEDIUM5.3same product

Apache Airflow FAB Auth Manager zawiera podatność LDAP filter injection (CWE-90), która pozwala nieuwierzyteln...

CVE-2025-24813CRITICAL9.8⚠ KEVPL ✓same vendor

Apache Tomcat: Path Equivalence prowadzący do RCE i ujawnienia danych